Impact
Stanza, a Stanford NLP Python library, contained a zip slip flaw in the function that extracts downloaded model archives. The vulnerability arises because the extraction routine passes archive members directly to zipfile.ZipFile.extractall without validating their paths. A malicious archive that includes parent-directory traversal entries can therefore write files outside the intended model directory, overwriting files that are writable by the Stanza process. Such overwrites can be leveraged to modify shell configuration, SSH authorization data, Python packages, or executable scripts, thereby enabling arbitrary code execution.
Affected Systems
The affected product is Stanford NLP Stanza. Versions earlier than 1.14.0 are susceptible, as the cracking extraction logic is present only in those releases.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, and the EPSS score of less than 1% points to a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through the Stanza download or installation process; an adversary could supply a crafted archive via the internet or a malicious internal source. If executed, the exploit would allow overwrite of privileged files and potentially remote code execution. This risk is elevated if the Stanza process runs with elevated permissions or in a multi-user environment.
OpenCVE Enrichment